LockGrowth - Locksmith Growth Platform
UK GDPR & Data Protection Act Compliant

Privacy Policy

This Privacy Policy explains how Atypikal Lead Capture & Instant Quote collects, processes, stores, and protects personal information in accordance with the UK General Data Protection Regulation (UK GDPR) and the UK Data Protection Act 2018.

Policy Versionv1.0
Effective Date2026-07-30
Last Updated2026-07-30
1

Data Controller

Atypikal Studio operates as the primary Data Controller for the LockGrowth - Locksmith Growth Platform hosted at https://lockquote.atypikalstudio.dev.

Where LockGrowth is embedded onto third-party locksmith websites, Atypikal Studio and the subscriber business (the locksmith tenant) act as Data Controllers for customer lead enquiries captured through the widget.

2

Contact Details

If you have questions regarding this Privacy Policy, wish to exercise your legal data protection rights, or have concerns about how your data is managed, please contact our Data Protection Officer (DPO):

3

Information We Collect

We collect personal information necessary to calculate instant lockout estimates, dispatch lead enquiries, and provide account access:

Data Categories Collected:

  • Identity Data: Full Name.
  • Contact Data: Telephone number, email address, UK postcode, and optional message details.
  • Locksmith Quote Data: Service requested (e.g. Locked Out, UPVC Door Lock, Lost Keys), Property Type, and Urgency Level.
  • Geographic Data: Geocoded coordinates (latitude & longitude) derived from UK postcode via OpenStreetMap/Nominatim API for technician dispatch.
  • Technical & System Data: IPv6 address, browser type, device descriptors, timestamp logs, and authentication tokens for platform tenant accounts.
4

Lawful Basis for Processing

Under UK GDPR Article 6, we process personal data under the following lawful bases:

  1. Performance of a Contract (Art. 6(1)(b)): Processing lead details submitted via the quote wizard to deliver requested locksmith estimates and enable dispatch services.
  2. Legitimate Interests (Art. 6(1)(f)): Maintaining platform security, monitoring quote conversion analytics, dedicated data isolation, and preventing fraudulent lead submissions.
  3. Consent (Art. 6(1)(a)): Explicit consent provided by users checking the consent confirmation box prior to quote estimation.
5

How Information Is Used

Personal data collected through the Lead Capture & Instant Quote platform is used strictly for operational purposes:

  • Generating accurate, instant price ranges for locksmith services.
  • Transmitting immediate lead alerts (Email) to authorized locksmith technicians for fast response.
  • Displaying lead pipeline data in the locksmith SaaS dashboard (Kanban & Lead log).
  • Maintaining tenant-isolated audit logs for security and compliance records.
6

Third-Party Processors

We partner with established cloud service providers to power platform features. All sub-processors adhere to strict UK GDPR data processing agreements:

Supabase (PostgreSQL & Auth)Database storage & encrypted authentication credentials.
Resend Inc.Transactional lead notification emails to locksmith businesses.
OpenStreetMap / Nominatim APIUK postcode geocoding for technician proximity calculation.
7

Data Retention

We retain personal lead records and generated quote data for no longer than necessary to fulfill the operational purpose for which it was collected.

The default platform retention period is configured to 365 days (1 year), after which lead records and audit logs are safely anonymized or purged in compliance with UK DPA standards.

8

Security Measures

We employ industry-standard technical and organizational safeguards to ensure data protection:

  • Tenant Isolation: Strict database Row Level Security (RLS) policies preventing cross-tenant data leakage.
  • Encryption: TLS/SSL encryption for data in transit and AES-256 encryption at rest.
  • Input Validation: Zod schema validation and CSRF protection on all API endpoints.
  • Access Control: Passwordless Supabase authentication for admin accounts.
9

Your Rights Under UK GDPR

Under the UK GDPR, individuals possess key data protection rights regarding their personal information:

  • Right of Access: Request a copy of the personal data held about you (Subject Access Request).
  • Right to Rectification: Request correction of inaccurate or incomplete personal records.
  • Right to Erasure (Right to be Forgotten): Request deletion of your personal data where no legal override exists.
  • Right to Restrict Processing: Request temporary restriction of data processing in specified scenarios.
  • Right to Data Portability: Obtain your personal data in a structured, machine-readable format.
  • Right to Object: Object to processing based on legitimate interests.
10

Contacting the Information Commissioner's Office (ICO)

If you are dissatisfied with how we handle your personal data, you have the right to lodge a formal complaint with the UK supervisory authority:

Information Commissioner's Office (ICO)

Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF

Helpline: 0303 123 1113 | Website: https://ico.org.uk

11

Policy Version & Metadata

This document is version-controlled by the Compliance Service infrastructure. Current configuration attributes:

PRIVACY_POLICY_VERSION: 1.0

PRIVACY_POLICY_EFFECTIVE_DATE: 2026-07-30

PRIVACY_POLICY_LAST_UPDATED: 2026-07-30

DEFAULT_RETENTION_DAYS: 365

12

Policy Revisions & Updates

We may update this Privacy Policy periodically to reflect technological updates, regulatory changes under UK GDPR, or changes to platform services.

Material revisions will be published on this page with an updated version number and last revised date. We encourage users to check this page periodically.

Privacy Policy | LockGrowth - Locksmith Growth Platform